Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,100 rules
SystemNightmare by GentilKiwi - External Printer Mapped - CVE-2021-1675 / CVE-2021-34527 (via security)
This rule detects exploit the PrintNightmare vulnerability by abusing the Windows print spooler using the service exposed by Gentilkiwi.
HuntRule TeamWindowssecurityHigh50Premium2026-09-01Obfuscated RDP Tunneling Configuration Enabled for Port Forwarding (via process_creation)
This rule detects configure port forwarding on a host to redirect traffic to a C&C target.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-01Malicious Metasploit Reverse Shell Injection in SQL Server (via process_creation)
This rule detects inject a payload into SQL Server in order to obtain a remote shell.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-01Malicious Impacket WMIexec Process Execution (via process_creation)
This rule detects execute WMIexec in order to escalate privileges.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-01Malicious Fortinet APT Group Abuse on Windows - User (via security)
This rule detects scenarios where APT actors exploits Fortinet vulnerabilities to gain access into Windows infrastructure.
HuntRule TeamWindowssecurityHigh40Premium2026-09-01Malicious Service Abuse with Backdoored "command Failure" - Reg via PowerShell (via powershell)
This rule detects modify the configuration of a service to trigger an action when the service is crashed.
HuntRule TeamWindowspowershellHigh60Premium2026-09-01Malicious Rubeus Kerberos Unconstrained Delegation Abuse (via security)
This rule detects abuse Kerberos unconstrained delegation for domain persistence.
HuntRule TeamWindowssecurityHigh50Premium2026-09-01Malicious Stickey Key Called CMD via Command Execution - Hash Detection (via process_creation)
This rule detects calls the stickey key and execute CMD.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-01MuddyWater NetBird Deployment via Hardcoded Setup Key (via process_creation)
This rule detects NetBird being configured with the hardcoded setup key reused across MuddyWater samples targeting CFOs, a remote-access persistence behavior. Adversaries leverage a known setup key to silently enroll compromised hosts into their NetBird overlay network for hands-on access.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-01Malicious Firewall Deactivation - Firewall (via firewall-as)
This rule detects disabled the Windows Firewall to evade defense.
HuntRule TeamWindowsfirewall-asHigh50Premium2026-09-01Malicious Microsoft Defender Threat Exclusion Added - Native (via windefend)
This rule detects scenarios where a threat exclusion is added to the antivirus in order to bypass its detection capacities.
HuntRule TeamWindowswindefendHigh90Premium2026-09-01AsyncRAT Injector libPK.dll Written to Public Folder (via file_event)
This rule detects the native injector libPK.dll being written into the C users Public folder, a staging behavior of the AsyncRAT chain that later calls its Execute export to inject the payload. Adversaries leverage the shared Public directory to drop the injector where any user context can reach it.
HuntRule TeamWindowsfile_eventMedium20Premium2026-09-01FunkSec Ransomware Encryption Artifacts via funksec Extension and Markdown Ransom Note (via file_event)
This rule detects the on-disk artifacts of FunkSec ransomware, namely files renamed with the funksec extension and the dropped README markdown ransom note. Adversaries append a unique extension and write a ransom note during mass encryption, so these artifacts confirm active data-encryption for impact.
HuntRule TeamWindowsfile_eventHigh80Premium2026-09-01Malicious XE Group Webshell Upload via VeraCore UploadImage CVE-2024-57968 (via webserver)
This rule detects abuse of the VeraCore UploadImage handler to upload an ASP or ASPX webshell through the CVE-2024-57968 unrestricted-upload flaw exploited by XE Group. The request combines the PMA upload controller with a script-file filename parameter, reflecting the point at which the actor plants a persistent webshell on the server.
HuntRule TeamWebwebserverHigh110Premium2026-09-01HamsaUpdate Wiper Trigger via F5UPDATER ConfirmDeleteFiles Argument (via process_creation)
This rule detects execution of the F5UPDATER wiper masquerading as an F5 update tool with the ConfirmDeleteFiles argument that triggers destructive file deletion without a confirmation prompt in Operation HamsaUpdate against Israeli infrastructure. The specific loader name paired with this argument marks the transition from staging to data destruction.
HuntRule TeamWindowsprocess_creationHigh120Premium2026-09-01